[ANN] OpenResty 1.25.3.2 released

Mathew Heard me at mheard.com
Mon Jul 22 08:09:40 UTC 2024


Now that there is a patch out could you please share more information
on those "specific circumstances"?

It looks to me that luajit2 does not support SSE4.2 whereas agentzh's
fork does. And this is what has been disabled in this release. Is this
an interim release while the cause is investigated or is it fully
understood?

On Mon, 22 Jul 2024 at 17:46, Jiahao Wang via nginx <nginx at nginx.org> wrote:
>
> Hi folks,
>
> I am happy to announce the new formal release, 1.25.3.2, of our OpenResty web platform based on NGINX and LuaJIT.
>
> OpenResty 1.25.3.2 is a security update addressing a performance issue in our OpenResty branch of LuaJIT related to hash computation optimization. This update disables a specific optimization in our LuaJIT fork that could potentially lead to performance degradation under certain circumstances (CVE-2024-39702).
>
> It's important to note that this issue is specific to our OpenResty branch of LuaJIT and does not affect the upstream mainline LuaJIT.
>
> We would like to express our gratitude to Zhongwei Yao from Kong INC. for reporting this issue.
>
> The full announcement, download links, and change logs can be found below:
>
> http://openresty.org/en/ann-1025003002.html
>
> You can download the software packages here:
>
> https://openresty.org/en/download.html
>
> OpenResty is a high performance and dynamic web platform based on our enhanced version of Nginx core, our enhanced version of LuaJIT, and many powerful Nginx modules and Lua libraries. See OpenResty's homepage for details:
>
> https://openresty.org/en/
>
> We strongly recommend all users to upgrade to this version to ensure optimal performance and security.
>
> OpenResty Inc. provides commercial support and private module development for the open-source OpenResty. For more information, please visit https://openresty.com.
>
> Enjoy!
>
> Best regards,
> Jiahao
> _______________________________________________
> nginx mailing list
> nginx at nginx.org
> https://mailman.nginx.org/mailman/listinfo/nginx


More information about the nginx mailing list